Junglewise Threat Intelligence

CVE-2026-57677: Novalnet Payment Gateway for WooCommerce PHP object injection

CVE-2026-57677 · Severity: critical · CVSS 9.8 · Published 2026-07-02

Executive brief

A critical vulnerability exists in the Novalnet Payment Gateway plugin for WooCommerce, which is used to process online payments for WordPress-based stores. An attacker can exploit this flaw without needing a password to potentially take full control of the website, steal customer data, or disrupt business operations. Business owners should immediately update the plugin to version 12.10.4 to prevent unauthorized access.

Technical details

The Novalnet Payment Gateway for WooCommerce plugin (versions <= 12.10.3) is vulnerable to PHP Object Injection due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable POP (Property Oriented Programming) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file access. The issue is resolved in version 12.10.4.

Affected products

  • Novalnet Novalnet Payment Gateway for WooCommerce <= 12.10.3

Timeline

  • 2026-06-15: other: Reported by researcher qdtad
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published to NVD dataset
  • 2026-07-02: patched: Patch confirmed available in version 12.10.4

References